LOGO

FTC Requires Health Apps to Report Data Breaches | Data Security

September 16, 2021
FTC Requires Health Apps to Report Data Breaches | Data Security

FTC Strengthens Health Data Breach Notification Rules

The U.S. Federal Trade Commission (FTC) has issued a warning to application developers and device manufacturers. Any entity collecting personal health information is now required to inform consumers promptly about data breaches or unauthorized sharing of their data.

Policy Clarification and Expanded Scope

In a recent 3-2 decision, the FTC formalized a new policy statement. This clarifies the 2009 Health Breach Notification Rule, initially designed for companies managing health records. The updated rule now explicitly includes health apps and devices in its purview.

Specifically, applications tracking sensitive data like fertility, fitness levels, and blood glucose are targeted. FTC Chair Lina Khan emphasized that these often lack sufficient investment in data security and user privacy.

Concerns Regarding Data Security Practices

Khan stated that digital applications frequently demonstrate a disregard for user data protection. This leaves sensitive health information vulnerable to both hacking attempts and security breaches.

A study published in the British Medical Journal this year highlighted significant issues within health apps. These range from insecure data transmission to the unauthorized disclosure of user information to advertising networks.

Recent High-Profile Data Breaches

Several recent incidents have underscored these concerns. Babylon Health, a telehealth startup, experienced a breach due to a software error, exposing video consultations of multiple patients.

Furthermore, the period tracking app Flo was found to be sharing user health data with third-party analytics and marketing services without explicit consent.

Notification Requirements and Definition of a Breach

The revised rule mandates that any company offering health apps or connected fitness devices notify consumers if their personal health data is compromised.

Importantly, a “data breach” isn’t limited to cybersecurity intrusions. Unauthorized access, including the sharing of information without permission, also triggers notification obligations.

Addressing the Commodification of Health Data

Khan expressed concern that the core issue lies in the commercialization of sensitive health information. Companies often leverage this data for behavioral advertising and user analytics.

Enforcement and Penalties

The FTC has pledged to “vigorously” enforce the new rule. Non-compliance will result in fines of $43,792 per violation, per day.

Recent FTC Actions on Privacy

This action follows other recent FTC efforts to combat privacy violations. The agency recently unanimously voted to ban SpyFone and its CEO, Scott Zuckerman, from the surveillance industry.

This ban stemmed from the company’s practice of harvesting mobile data from thousands of individuals and leaving it publicly accessible.

#FTC#health apps#data breach#data security#privacy#fines